CVE-2023-24809
Published on: Not Yet Published
Last Modified on: 02/28/2023 07:25:00 PM UTC
Certain versions of Nethack from Nethack contain the following vulnerability:
NetHack is a single player dungeon exploration game. Starting with version 3.6.2 and prior to version 3.6.7, illegal input to the "C" (call) command can cause a buffer overflow and crash the NetHack process. This vulnerability may be a security issue for systems that have NetHack installed suid/sgid and for shared systems. For all systems, it may result in a process crash. This issue is resolved in NetHack 3.6.7. There are no known workarounds.
- CVE-2023-24809 has been assigned by
security-adviso[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
NetHack - NetHack version = >= 3.6.2, < 3.6.7
CVSS3 Score: 5.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
NetHack Call command buffer overflow · Advisory · NetHack/NetHack · GitHub | github.com text/html |
![]() |
NetHack 3.6.7: CVE-2023-24809 | nethack.org text/html |
![]() |
Related QID Numbers
- 503199 Alpine Linux Security Update for nethack
Exploit/POC from Github
NetHack is a single player dungeon exploration game. Starting with version 3.6.2 and prior to version 3.6.7, illegal …
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Nethack | Nethack | All | All | All | All |
- cpe:2.3:a:nethack:nethack:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-24809 : NetHack is a single player dungeon exploration game. Starting with version 3.6.2 and prior to vers… twitter.com/i/web/status/1… | 2023-02-17 20:06:28 |
![]() |
CVE-2023-24809 | 2023-02-17 21:38:26 |